Following the Executive Order on post-quantum cryptography (PQC), Simon Pamplin, CTO at Certes, commented:
This Executive Order confirms what has been treated as a forward-looking concern is now a federal mandate with fixed deadlines. Setting 2030 and 2031 timelines for high value assets removes the ambiguity that has allowed many organisations to treat post-quantum migration as a future problem rather than a present one.
What stands out most is the focus on migration as a coordination challenge rather than a simple upgrade. Directing agencies to designate a dedicated PQC migration lead reflects an understanding that this cannot be solved by patching individual systems. Cryptographic dependencies are embedded across hardware, software and communications infrastructure that has often been in place for decades, and untangling that requires sustained organisational effort, not a single technical fix.
The Order’s emphasis on critical infrastructure is also significant. Power grids, water systems and transportation networks were not built with cryptographic agility in mind. Many run on legacy technology that cannot simply be replaced wholesale. That makes the approach to protection just as important as the timeline. Securing data flowing through ageing infrastructure requires controls applied to the data itself, rather than solutions that assume infrastructure can be modernised at the same pace as the threat.
The harvest now, decrypt later risk is precisely why these deadlines matter today rather than closer to 2030. Data deemed sensitive now, including national security information and infrastructure operational data, can be intercepted and stored years before quantum capability matures, then decrypted retroactively. A 2030 deadline does not protect data being harvested in 2026.
Federal action of this scale typically becomes the benchmark private sector organisations are measured against, particularly in regulated industries. The organisations that begin treating data protection as quantum-safe and data-centric now, rather than waiting for compliance deadlines, will be the ones positioned ahead of both the threat and the regulation.
Editor’s note: Simon Pamplin will be speaking at PQC+IQT, which is coming to New York City on October 26.



